Re: LPRng/rhs-printfilters - remote execution of commands

From: Matt Bing (mbingat_private)
Date: Mon Aug 27 2001 - 13:54:35 PDT

  • Next message: Margaret CTR Rhodes: "WIN2000 and IIS"

    > RedHat 7.0 (possibly others)
    
    Redhat 7.1 is not vulnerable. If tetex-dvips is installed, the filter
    /usr/share/printconf/mf_rules/mf40-tetex_filters contains the '-R' 
    switch:
    
    #
    # tetex filters
    #
    
    /dvi/  fpipe/postscript/       /usr/bin/dvips -t PAGEsize ifdef(`XDPI',-X XDPI -Y YDPI, ifdef(`DPI',-D DPI,-D 600)) -R -q -f $FILE
    
    -- 
    Matt Bing
    NFR Security
    Rapid Response Team
    



    This archive was generated by hypermail 2b30 : Mon Aug 27 2001 - 14:17:02 PDT